@tryghost/ghst
A modern Ghost CMS CLI
18
Versions
MIT
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
gitHead linked
Maintainers
zimoatghostallouiskernalghostchrisraibleerisdsjohnonolankevinansfieldcobbspuraileencgnjlohminimaluminiumsam-lordpauladamdavisbobvaneckjoeegrigghadretjonhickmanerik-ghostsagzyvershwalzach1618mike182ukluissazevedolsingernickmoretonrenatoworksrblstr-ghostevanhahn-ghostaustin.burdineweylandswartghost-slimertmciescojonatan-ghost9larsons
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Transition to GitHub Actions CI publishing on official TryGhost package; legitimate. | ai | |
| dependencies | unvetted-dep:@jq-tools/jq | AI (dependencies): Small utility dep, no fetch/exec behavior, low risk. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): Single benign jq wrapper added, not a supply-chain pattern match. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): TryGhost org package published via GitHub Actions with SLSA provenance; maintainer additions are expected for an active org project. | ai | |
| dependencies | unvetted-dep:gscan | AI (dependencies): gscan is the official Ghost theme validator, a well-known TryGhost ecosystem package. | ai | |
| dependencies | unvetted-dep:markdown-it | AI (dependencies): markdown-it is a widely-used, well-maintained markdown parser with no malicious indicators. | ai | |
| phantom-deps | phantom-dep:@tryghost/mg-json | AI (phantom-deps): Same-org migration utility; used in CLI sub-commands, stable false positive. | ai | |
| phantom-deps | phantom-dep:@tryghost/mg-wp-xml | AI (phantom-deps): Same-org migration utility; used in CLI sub-commands, stable false positive. | ai | |
| typosquat | typosquat.levenshtein:jest | AI (typosquat): @tryghost/ghst is 'Ghost' abbreviated under the official TryGhost org scope; not a typo of jest. | ai | |
| phantom-deps | phantom-dep:@tryghost/mg-medium-export | AI (phantom-deps): Same-org migration utility; used in CLI sub-commands, stable false positive. | ai | |
| phantom-deps | phantom-dep:@tryghost/mg-substack | AI (phantom-deps): Same-org migration utility; used in CLI sub-commands, stable false positive. | ai | |
| typosquat | typosquat.levenshtein:got | AI (typosquat): @tryghost/ghst is 'Ghost' abbreviated under the official TryGhost org scope; not a typo of got. | ai | |
| phantom-deps | phantom-dep:ink | AI (phantom-deps): CLI tool using ink/react for terminal UI; may be used indirectly via dynamic imports or sub-commands. | ai | |
| phantom-deps | phantom-dep:ora | AI (phantom-deps): CLI spinner library; likely used in sub-commands or dynamically loaded CLI features. | ai | |
| phantom-deps | phantom-dep:conf | AI (phantom-deps): Config persistence library for CLI; may be used indirectly in sub-commands. | ai | |
| phantom-deps | phantom-dep:react | AI (phantom-deps): Required peer dep for ink terminal UI framework; stable false positive for this CLI package. | ai |
Versions (showing 18 of 18)
| Version | Deps | Published |
|---|---|---|
| 0.16.2 | 19 / 10 | |
| 0.16.0 | 19 / 10 | |
| 0.15.3 | 18 / 9 | |
| 0.15.2 | 18 / 9 | |
| 0.15.1 | 18 / 9 | |
| 0.15.0 | 18 / 9 | |
| 0.14.1 | 18 / 9 | |
| 0.14.0 | 18 / 9 | |
| 0.13.0 | 18 / 9 | |
| 0.11.0 | 18 / 9 | |
| 0.10.0 | 18 / 9 | |
| 0.8.0 | 18 / 9 | |
| 0.7.0 | 18 / 9 | |
| 0.5.0 | 18 / 9 | |
| 0.4.3 | 18 / 9 | |
| 0.4.2 | 18 / 9 | |
| 0.4.1 | 18 / 9 | |
| 0.4.0 | 18 / 9 |
v0.16.2
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.16.0
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.15.3
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.15.2
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.